ScreenshotNeo

BlogAI agents

What Is Amazon MCP and How Does It Work?

Amazon MCP usually means AWS’s use of the Model Context Protocol. Learn how clients discover tools, call AWS services, and secure MCP integrations.

By the ScreenshotNeo team1 October 20266 min read

Amazon MCP usually means Amazon Web Services’ use of the Model Context Protocol (MCP). MCP is an open client-server standard: an AI application connects to an MCP server, discovers its capabilities, and invokes tools or reads resources through standardized messages. The server performs the operation against an external system and returns structured results for the assistant.

AWS Marketplace MCP is one concrete implementation. It helps an AI application find, evaluate, research, and prepare proposals for AWS Marketplace solutions. You do not need an MCP server to use ordinary Amazon services; you need one when an AI client must interact with an external capability through the MCP interface.

Amazon MCP in one request

  1. An AI application acts as the MCP client.
  2. The client connects to a compatible server over its supported transport.
  3. It discovers tools and their JSON schemas, commonly with tools/list.
  4. The model selects a tool and the client sends a structured tools/call request.
  5. The server validates inputs, performs the operation, and returns structured content.
  6. The assistant uses that result in its answer or in a larger agent workflow.

AWS describes MCP as an open standard that lets AI applications communicate with external tools and data sources. The protocol improves interoperability, but the server owner still has to build authentication, authorization, schemas, error handling, logging, testing, and documentation.

What MCP exposes

Capability Purpose Example
Tools Callable functions that perform work Search an AWS Marketplace catalog
Resources Data or context an AI application can read Reference documentation or account data
Prompts Reusable templates for structuring interactions A guided research prompt

A server may expose any combination of these capabilities. A read-only research server has a different risk profile from one that can mutate cloud resources.

AWS Marketplace MCP example

AWS Marketplace MCP documents six stateless tools for Marketplace discovery and research: report guidelines, solution search, solution details, related solutions, deep solution research, and feedback. Its documented endpoint is https://marketplace-mcp.us-east-1.api.aws/mcp. The API reference describes MCP over Streamable HTTP with JSON-RPC 2.0, and the documented service endpoint requires no authentication.

The endpoint is an MCP server, not a general-purpose replacement for every AWS API. Its available tools and schemas define what an agent can do.

How capability discovery works

Clients normally begin with an initialize exchange. The client and server advertise protocol information and capabilities. The client then calls tools/list and receives tool names, descriptions, and input schemas. A capable client can present those tools to a model, validate arguments, and route the model’s selected call to the server.

{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}

A simplified tool call looks like this:

{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"solution_search","arguments":{"query":"observability"}}}

The exact tool name and argument schema come from the server’s discovery response. Do not hard-code assumptions when a client can retrieve the schema.

Calling an MCP endpoint with cURL

For a Streamable HTTP server, send JSON-RPC requests with an HTTP client. The following pattern is illustrative; use the tool name and arguments returned by tools/list.

curl -X POST "https://marketplace-mcp.us-east-1.api.aws/mcp" \
  -H "Content-Type: application/json" \
  --data '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'

For production clients, handle the response as JSON, preserve the request ID, and inspect protocol errors as well as HTTP status codes.

Calling MCP from Python

import requests

endpoint = "https://marketplace-mcp.us-east-1.api.aws/mcp"
payload = {
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/list",
    "params": {},
}
response = requests.post(endpoint, json=payload, timeout=30)
response.raise_for_status()
print(response.json())

After discovery, send a second request with method set to tools/call, the discovered tool name, and arguments matching its JSON Schema.

Calling MCP from Node.js

const endpoint = 'https://marketplace-mcp.us-east-1.api.aws/mcp';

const response = await fetch(endpoint, {
  method: 'POST',
  headers: { 'content-type': 'application/json' },
  body: JSON.stringify({
    jsonrpc: '2.0',
    id: 1,
    method: 'tools/list',
    params: {}
  })
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());

Transport, sessions, and protocol versions

Confirm whether the server supports Streamable HTTP, another transport, or both. Also verify the protocol version supported by both client and server. AgentCore documentation notes that MCP versions through 2025-11-25 require stateful mode for elicitation and sampling because those requests use an open session. For version 2026-07-28 and later, multi-round-trip requests can support those interactions without stateful mode. A client should negotiate capabilities instead of assuming a version.

Security and production design

  • Least privilege: grant only the permissions required by each tool.
  • Validate inputs: enforce JSON Schema, bounds, allowed identifiers, and content limits on the server.
  • Separate read and write tools: make destructive operations explicit and require confirmation in the client.
  • Authenticate and authorize: use the server’s supported identity and session model; do not put long-lived secrets in prompts.
  • Log safely: record tool name, caller, request ID, latency, outcome, and a redacted argument summary.
  • Isolate execution: sandbox scripts and constrain network and filesystem access when tools execute code.
  • Document failures: return actionable, structured errors instead of exposing internal traces.

Reliability and performance checklist

  • Cache stable discovery results, while respecting server changes.
  • Set connection and operation timeouts separately.
  • Retry only transient transport failures, with exponential backoff and an idempotency strategy.
  • Keep tool schemas narrow so models select the right operation.
  • Paginate large results and cap response size.
  • Track request IDs through the agent, client, and server logs.
  • Test malformed arguments, unavailable dependencies, expired sessions, and partial failures.

Latency includes connection setup, capability discovery, the external operation, and model processing. Stateless tools simplify horizontal scaling; stateful interactions require session affinity or a shared session store.

Common errors and fixes

Symptom Likely cause Fix
404 or method not found Wrong endpoint or unsupported transport Use the documented MCP endpoint and transport.
Invalid JSON-RPC request Missing jsonrpc, id, method, or params Send a JSON-RPC 2.0 object with the required fields.
Tool not found Hard-coded or outdated tool name Call tools/list and use the returned name.
Invalid arguments Arguments do not match the tool schema Validate against the discovered JSON Schema.
401 or 403 Missing or insufficient credentials Configure the server’s documented authentication and least-privilege permissions.
Timeouts Slow upstream service or limits too low Set bounded timeouts, retry transient failures, and reduce result size.
Session errors Client and server disagree about stateful behavior Check negotiated protocol version and session requirements.
Model makes unsafe changes Mutation tool lacks confirmation or scope controls Separate write tools, require explicit approval, and enforce authorization server-side.

Amazon MCP versus ordinary AWS APIs

An AWS SDK or service API gives application code a specific, documented interface. MCP adds a common discovery and invocation layer so different AI clients can use compatible tools without a separate bespoke integration for every client. MCP does not grant AWS permissions by itself and does not remove the need for service authentication, authorization, quotas, and error handling.

Or skip the browser setup

If your agent needs visual evidence from a webpage, ScreenshotNeo is the first screenshot API to try: it removes cookie banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, timeouts, failed loads, and cache hits are never billed; and its MCP server lets Claude, Cursor, or another MCP client take screenshots.

See the ScreenshotNeo API documentation for all options. A single request returns an image or PDF:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo includes full-page and element captures, device presets, custom headers and cookies, waits, blocking rules, PDFs, signed links, async jobs, bulk capture, and a usage API. It provides X-Page-Verdict and X-Billed headers so clients can see whether a response was a clean shot and billed. The free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

FAQ

Is Amazon MCP the same as MCP?

No. MCP is the general open standard; Amazon MCP usually refers to AWS implementations such as AWS Marketplace MCP.

Do I need an MCP server to use Amazon services?

No. Use AWS SDKs, command-line tools, or service APIs when those fit your application. Use MCP when an AI client needs standardized discovery and tool calls.

Can an MCP server change AWS resources?

It can expose mutation tools, but permissions and confirmations are the server and client’s responsibility. Treat write operations as higher risk than read-only tools.

Is AWS Marketplace MCP authenticated?

The documented AWS Marketplace MCP endpoint requires no authentication. Other MCP servers may require authentication and authorization.

What should I check before connecting a client?

Verify transport, protocol version, tool schemas, authentication, session behavior, response limits, and whether tools are read-only or mutating.